Skip to content

fix(security): workflow permissions and two e2e regexes - #43

Merged
DarrellVS merged 1 commit into
devfrom
26-codeql-workflows
Sep 22, 2026
Merged

DarrellVS merged 1 commit into
devfrom
26-codeql-workflows

Conversation

@DarrellVS

Copy link
Copy Markdown
Owner

Closes #26. Code scanning alerts 1, 2, 6, 16.

  • Missing workflow permissions (1, 2): ci.yml and publisher-image.yml get permissions: contents: read. Neither needs the token to write (the image goes to Docker Hub with its own credentials; the gha layer cache uses the runner's token). The other three workflows already declared theirs.
  • Polynomial regex in e2e (6, 16): the fake publishers compared /^Bearer\s+(.+)$/; now an exact equality with the header GoodBit sends, which is what the test is checking anyway.
  • Em dashes out of the two workflow comments.

Gate: compress.spec.ts + publishGoodBits.spec.ts, 10 passed; typecheck green.

🤖 Generated with Claude Code

Closes #26.

**Both workflows without a `permissions` block now read and nothing
else.** `ci.yml` only typechecks and `publisher-image.yml` pushes to
Docker Hub with its own credentials, so neither needs the GitHub token to
write anything, and without the block it gets the repository's default.
`release.yml`, `pages.yml` and `dev-sync.yml` already declared theirs.

**The e2e fake publishers compare the header whole.** Both parsed it with
`/^Bearer\s+(.+)$/`, the same quadratic shape the real publisher just
lost. In a test the exact header GoodBit sends is the thing being
checked, so an equality says more than a parse did.

The em dashes in the two workflow comments go too.

`compress.spec.ts` and `publishGoodBits.spec.ts`: 10 passed.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@DarrellVS DarrellVS added this to the 3.5.0 milestone Sep 22, 2026
@DarrellVS DarrellVS added the security Code scanning and hardening label Sep 22, 2026
@DarrellVS DarrellVS self-assigned this Sep 22, 2026
@DarrellVS
DarrellVS merged commit 6ff4833 into dev Sep 22, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security Code scanning and hardening

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant